पाठ 13 / 28
URLs fetch करने वाले Tools: SSRF और Allow-Lists
Browsing tool को आंतरिक systems तक पहुँचने से रोकें।
Server हमलावर की ओर से fetch करता है
"यह URL fetch करो" tool आपके server पर, आपके network के भीतर चलता है। मॉडल (या injected निर्देश) कोई भी URL चुन सके, तो हमलावर आपके server से आंतरिक सेवाओं (http://localhost, 169.254.169.254 जैसे cloud metadata endpoint, admin panel) को अनुरोध करवाकर उत्तर पढ़ सकता है: server-side request forgery (SSRF)। बचाव: tool जिन hosts से संपर्क कर सके उनकी allow-list; https अनिवार्य; URL ठीक से parse करें और असली hostname की तुलना करें (substring नहीं: docs.example.com@evil.test और docs.example.com.evil.test जाल हैं); DNS resolution के बाद निजी और link-local IP सीमाएँ रोकें, और redirects दोबारा जाँचें; ports, response आकार और समय सीमित करें; और fetcher को आंतरिक सेवाओं या credentials तक पहुँच रहित अलग network खंड में चलाएँ।
चालों से बचने वाली URL allow-list, चलाकर
मैंने यह सादे Python 3 (सिर्फ़ standard library) से चलाया। यहाँ सारे हमले स्थानीय डेटा पर हानिरहित प्रदर्शन हैं, कोई असली system उपयोग नहीं हुआ। सिर्फ़ अनुमत host का सादा https URL पास होता है। सादा http, मिलता-जुलता subdomain, user@host चाल, cloud metadata पता और non-standard port सब अस्वीकृत हैं। असली बचाव resolved IP पते और redirects भी जाँचता है।
from urllib.parse import urlparse
ALLOWED_HOSTS = {"docs.example.com", "api.example.com"}
def allowed(url):
u = urlparse(url)
return u.scheme == "https" and u.hostname in ALLOWED_HOSTS and u.username is None and u.port in (None, 443)
for url in ["https://docs.example.com/page", "http://docs.example.com/page", "https://docs.example.com.evil.test/x",
"https://docs.example.com@evil.test/x", "https://169.254.169.254/latest/meta-data", "https://docs.example.com:8443/x"]:
print(f"{allowed(url)!s:5} {url}")
Output:
True https://docs.example.com/page False http://docs.example.com/page False https://docs.example.com.evil.test/x False https://docs.example.com@evil.test/x False https://169.254.169.254/latest/meta-data False https://docs.example.com:8443/x
Redirects के बाद दोबारा जाँचें
अनुमत host आंतरिक पते पर redirect कर सकता है। हर hop validate करें।
त्वरित जाँच: URL में अनुमत domain "शामिल" है यह जाँचने की जगह parse किया hostname क्यों तुलना करें?
- Substring जाँचें धीमी हैं
- docs.example.com.evil.test जैसी चालें अनुमत नाम रखती हैं पर कहीं और जाती हैं
- Hostnames सिर्फ़ case-insensitive हैं
- कोई अंतर नहीं
Answer
docs.example.com.evil.test जैसी चालें अनुमत नाम रखती हैं पर कहीं और जाती हैं — पहले parse करें, फिर असली host की सटीक तुलना करें।